Lucene search

K
cve[email protected]CVE-2020-9235
HistorySep 03, 2020 - 7:15 p.m.

CVE-2020-9235

2020-09-0319:15:12
CWE-20
web.nvd.nist.gov
17
cve-2020-9235
information leak
huawei
honor 20 pro
smartphone security

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

5.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.7%

Huawei smartphones HONOR 20 PRO Versions earlier than 10.1.0.230(C432E9R5P1),Versions earlier than 10.1.0.231(C10E3R3P2),Versions earlier than 10.1.0.231(C185E3R5P1),Versions earlier than 10.1.0.231(C636E3R3P1);Versions earlier than 10.1.0.212(C432E10R3P4),Versions earlier than 10.1.0.213(C636E3R4P3),Versions earlier than 10.1.0.214(C10E5R4P3),Versions earlier than 10.1.0.214(C185E3R3P3);Versions earlier than 10.1.0.212(C00E210R5P1);Versions earlier than 10.1.0.160(C00E160R2P11);Versions earlier than 10.1.0.160(C00E160R2P11);Versions earlier than 10.1.0.160(C01E160R2P11);Versions earlier than 10.1.0.160(C00E160R2P11);Versions earlier than 10.1.0.160(C00E160R8P12);Versions earlier than 10.1.0.230(C432E9R5P1),Versions earlier than 10.1.0.231(C10E3R3P2),Versions earlier than 10.1.0.231(C636E3R3P1);Versions earlier than 10.1.0.225(C431E3R1P2),Versions earlier than 10.1.0.225(C432E3R1P2) contain an information vulnerability. A module has a design error that is lack of control of input. Attackers can exploit this vulnerability to obtain some information. This can lead to information leak.

Affected configurations

NVD
Node
huaweihonor_20_pro_firmwareRange<10.1.0.230\(c432e9r5p1\)
AND
huaweihonor_20_proMatch-
Node
huaweihonor_20_pro_firmwareRange<10.1.0.231\(c10e3r3p2\)
AND
huaweihonor_20_proMatch-
Node
huaweihonor_20_pro_firmwareRange<10.1.0.231\(c185e3r5p1\)
AND
huaweihonor_20_proMatch-
Node
huaweihonor_20_pro_firmwareRange<10.1.0.231\(c636e3r3p1\)
AND
huaweihonor_20_proMatch-
Node
huaweihonor_view_20_firmwareRange<10.1.0.212\(c432e10r3p4\)
AND
huaweihonor_view_20Match-
Node
huaweihonor_view_20_firmwareRange<10.1.0.213\(c636e3r4p3\)
AND
huaweihonor_view_20Match-
Node
huaweihonor_view_20_firmwareRange<10.1.0.214\(c10e5r4p3\)
AND
huaweihonor_view_20Match-
Node
huaweihonor_view_20_firmwareRange<10.1.0.214\(c185e3r3p3\)
AND
huaweihonor_view_20Match-
Node
huaweioxfords-an00a_firmwareRange<10.1.0.212\(c00e210r5p1\)
AND
huaweioxfords-an00aMatch-
Node
huaweiprinceton-al10b_firmwareRange<10.1.0.160\(c00e160r2p11\)
AND
huaweiprinceton-al10bMatch-
Node
huaweiprinceton-al10d_firmwareRange<10.1.0.160\(c00e160r2p11\)
AND
huaweiprinceton-al10dMatch-
Node
huaweiprinceton-tl10c_firmwareRange<10.1.0.160\(c01e160r2p11\)
AND
huaweiprinceton-tl10cMatch-
Node
huaweitony-al00b_firmwareRange<10.1.0.160\(c00e160r2p11\)
AND
huaweitony-al00bMatch-
Node
huaweiyale-al00a_firmwareRange<10.1.0.160\(c00e160r8p12\)
AND
huaweiyale-al00aMatch-
Node
huaweiyale-l21a_firmwareRange<10.1.0.230\(c432e9r5p1\)
AND
huaweiyale-l21aMatch-
Node
huaweiyale-l21a_firmwareRange<10.1.0.231\(c10e3r3p2\)
AND
huaweiyale-l21aMatch-
Node
huaweiyale-l21a_firmwareRange<10.1.0.231\(c636e3r3p1\)
AND
huaweiyale-l21aMatch-
Node
huaweiyale-l61a_firmwareRange<10.1.0.225\(c431e3r1p2\)
AND
huaweiyale-l61aMatch-
Node
huaweiyale-l61a_firmwareRange<10.1.0.225\(c432e3r1p2\)
AND
huaweiyale-l61aMatch-

CNA Affected

[
  {
    "product": "HONOR 20 PRO;Honor View 20;OxfordS-AN00A;Princeton-AL10B;Princeton-AL10D;Princeton-TL10C;Tony-AL00B;Yale-AL00A;Yale-L21A;Yale-L61A",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Versions earlier than 10.1.0.230(C432E9R5P1),Versions earlier than 10.1.0.231(C10E3R3P2),Versions earlier than 10.1.0.231(C185E3R5P1),Versions earlier than 10.1.0.231(C636E3R3P1)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.1.0.212(C432E10R3P4),Versions earlier than 10.1.0.213(C636E3R4P3),Versions earlier than 10.1.0.214(C10E5R4P3),Versions earlier than 10.1.0.214(C185E3R3P3)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.1.0.212(C00E210R5P1)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.1.0.160(C00E160R2P11)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.1.0.160(C01E160R2P11)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.1.0.160(C00E160R8P12)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.1.0.230(C432E9R5P1),Versions earlier than 10.1.0.231(C10E3R3P2),Versions earlier than 10.1.0.231(C636E3R3P1)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.1.0.225(C431E3R1P2),Versions earlier than 10.1.0.225(C432E3R1P2)"
      }
    ]
  }
]

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

5.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.7%

Related for CVE-2020-9235